moov
Warn
Audited by Snyk on Apr 21, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W009: Direct money access capability detected (payment gateways, crypto, banking).
- Direct money access detected (high risk: 1.00). This skill is explicitly designed to interact with a payments platform (Moov) and provides mechanisms to perform account operations and transfers. It documents "Account
- Balance" and "Transfer", shows how to run pre-built actions via Membrane (membrane action run --connectionId=... ACTION_ID --json --input "{...}") and how to proxy arbitrary requests to the Moov API (membrane request CONNECTION_ID /path/to/endpoint with configurable HTTP methods and bodies). Those capabilities enable sending payments/payouts and managing accounts — i.e., directly executing financial transactions. Therefore it meets the criteria for Direct Financial Execution.
Issues (1)
W009
MEDIUMDirect money access capability detected (payment gateways, crypto, banking).
Audit Metadata